Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

11202
Total
755
Critical
3234
High
3640
Medium
CVE ID Severity Score Description Published
CVE-2026-4901 UNKNOWN Hydrosystem Control System saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the … Apr 09, 2026
CVE-2026-34538 MEDIUM 6.5 Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have DAG Run read permissions, such as … Apr 09, 2026
CVE-2026-34185 UNKNOWN Hydrosystem Control System is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject … Apr 09, 2026
CVE-2026-34184 UNKNOWN Hydrosystem Control System does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute … Apr 09, 2026
CVE-2026-34179 CRITICAL 9.1 In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for … Apr 09, 2026
CVE-2026-34178 CRITICAL 9.1 In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/container/backup.yaml, … Apr 09, 2026
CVE-2026-34177 CRITICAL 9.1 Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under … Apr 09, 2026
CVE-2025-62188 HIGH 7.5 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthorized actors to access sensitive information, including … Apr 09, 2026
CVE-2026-5854 CRITICAL 9.8 A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. … Apr 09, 2026
CVE-2026-5853 CRITICAL 9.8 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi-bin/cstecgi.cgi of the component … Apr 09, 2026
CVE-2026-5852 CRITICAL 9.8 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation … Apr 09, 2026
CVE-2026-5851 CRITICAL 9.8 A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The … Apr 09, 2026
CVE-2026-5850 CRITICAL 9.8 A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of … Apr 09, 2026
CVE-2026-5849 HIGH 7.3 A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a manipulation can lead … Apr 09, 2026
CVE-2026-5848 MEDIUM 4.7 A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getConnection of the file /drag/onlDragDataSource/testConnection of the component Data … Apr 09, 2026
CVE-2026-5847 MEDIUM 4.3 A vulnerability has been found in code-projects Movie Ticketing System 1.0. Impacted is an unknown function of the file /db/moviedb.sql of the component SQL Database … Apr 09, 2026
CVE-2026-5844 HIGH 7.2 A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the component HNAP1 SetNetworkSettings Handler. The manipulation … Apr 09, 2026
CVE-2026-5842 HIGH 7.3 A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the … Apr 09, 2026
CVE-2026-5841 HIGH 7.3 A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. Executing a manipulation can … Apr 09, 2026
CVE-2026-5840 MEDIUM 4.7 A security flaw has been discovered in PHPGurukul News Portal Project 4.1. Impacted is an unknown function of the file /admin/check_availability.php. Performing a manipulation of … Apr 09, 2026
CVE-2026-5839 MEDIUM 4.7 A vulnerability was identified in PHPGurukul News Portal Project 4.1. This issue affects some unknown processing of the file /admin/add-subcategory.php. Such manipulation of the argument … Apr 09, 2026
CVE-2026-5838 MEDIUM 4.7 A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the file /admin/add-subadmins.php. This manipulation of the argument sadminusername … Apr 09, 2026
CVE-2026-5742 MEDIUM 6.4 The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient input sanitization … Apr 09, 2026
CVE-2026-4336 MEDIUM 6.4 The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This … Apr 09, 2026
CVE-2026-1830 CRITICAL 9.8 The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient … Apr 09, 2026